2024-10-23 | 24015

Added · Updated

Guideline on Security Systems for Safeguarding Customer Information

Financial institutions must develop, document, and implement a written information security programme comprising administrative, technical, and physical safeguards appropriate to their size and complexity. The Board of Directors is required to approve the programme, set oversight policies, and receive annual reports on risk assessments, testing results, and security breaches. Management must establish internal controls, conduct regular independent testing, and ensure employees receive annual security training and background checks. Specific obligations include maintaining a six-year record retention period under the Proceeds of Crime Act, 2000, securing electronic data with encryption and firewalls, and enforcing contractual security measures for service providers.

Central Bank of Trinidad and Tobago logo

Trinidad and Tobago

Central Bank of Trinidad and Tobago

Scan of the document's first page
Share

CBTT published 6 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Source: Central Bank of Trinidad and Tobago — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from CBTT

CBTT published 6 documents in the last 30 days. We email you each new one the day it's published.